ncloud_secret_update_protection_key
Update a Secret Manager secret's KMS protection key to DEFAULT or USER_MANAGED_KEY by kmsKeyTag, changing how the secret is encrypted.
Instructions
Change the KMS protection key of a secret (DEFAULT service key or a USER_MANAGED_KEY by kmsKeyTag). kmsBoundaryType is required in the KR region (JPN is always ISOLATED).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| secretId | Yes | Secret ID (see ncloud_secret_list_secrets) | |
| kmsKeyTag | No | KMS key tag — required when protectionKeyType=USER_MANAGED_KEY | |
| keyIsolation | No | Which Secret Manager host to call: 'global' (default) for secrets encrypted with a KMS global key (secretmanager.apigw.ntruss.com); 'regional' for secrets encrypted with a KMS region-isolated key (ocapi-kr.ncloud.com/secretmanager — the only option in the JPN region) | global |
| kmsBoundaryType | No | KMS key isolation: GLOBAL or ISOLATED (required in KR) | |
| protectionKeyType | Yes | DEFAULT or USER_MANAGED_KEY |